SecurityFocus Newsletter #275

Peter Laborge <[email protected]> 16 Nov 2004 21:09:22 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #275
------------------------------

This Issue is Sponsored By: Symantec

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041116

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. The Worst Case Scenario
II. BUGTRAQ SUMMARY
     1. Gentoo Linux Multiple PDF EBuild Updates Unspecified Vulnera...
     2. Software602 602 LAN Suite Multiple Remote Denial Of Service ...
     3. Gentoo Portage Dispatch-Conf Insecure Temporary File Creatio...
     4. Gentoo Gentoolkit QPKG Insecure Temporary File Creation Vuln...
     5. Yukihiro Matsumoto Ruby CGI Module Unspecified Denial Of Ser...
     6. Sun Java Runtime Environment InitialDirContext Remote Denial...
     7. MiniShare Server Remote Buffer Overflow Vulnerability
     8. Microsoft Internet Explorer Local Resource Enumeration Vulne...
     9. Mantis Multiple Information Disclosure Vulnerabilities
     10. Nortel Contivity VPN Client Username Enumeration Vulnerabili...
     11. Samba Remote Wild Card Denial Of Service Vulnerability
     12. EGroupWare JiNN Application Unspecified Vulnerability
     13. Pavuk Multiple Unspecified Remote Buffer Overflow Vulnerabil...
     14. JAF CMS Directory Traversal Vulnerability Allowing Script Co...
     15. StarForce Professional Software Protection Local Privilege E...
     16. GFHost Cross-Site Scripting And Server-Side Script Execution...
     17. Up-IMAPProxy Multiple Remote Vulnerabilities
     18. Nucleus CMS Multiple Unspecified Input Validation Vulnerabil...
     19. Infusium ASP Message Board Multiple Unspecified Input Valida...
     20. SQLgrey Postfix Greylisting Service SQL Injection Vulnerabil...
     21. Netgear DG834 ADSL Firewall Router Multiple Vulnerabilities
     22. Samhain Labs Samhain Database Update Local Heap Overflow Vul...
     23. Sun One/IPlanet Messaging Server Webmail Unauthorized Email ...
     24. Microsoft Internet Explorer Embedded Content Status Bar URI ...
     25. Microsoft Windows DDEShare Buffer Overflow Vulnerability
     26. Kerio Personal Firewall IP Options Denial Of Service Vulnera...
     27. MTink Insecure Temporary File Creation Vulnerability
     28. PvPGN GameReport Packet Handler Remote Buffer Overflow Vulne...
     29. Multiple Vendor DNS Response Flooding Denial Of Service Vuln...
     30. Mozilla Firefox Download Dialogue Box File Name Spoofing Vul...
     31. Mozilla Firefox Insecure Default Installation Vulnerability
     32. WhitSoft Development SlimFTPd Remote Buffer Overflow Vulnera...
     33. Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vu...
     34. BNC getnickuserhost IRC Server Response Buffer Overflow Vuln...
     35. Multiple Browser IMG Tag Multiple Vulnerabilities
     36. Cisco IOS DHCP Input Queue Blocking Denial Of Service Vulner...
     37. BNC IRC Server Proxy Authentication Bypass Vulnerability
     38. WebCalendar Multiple Remote Vulnerabilities
     39. 04WebServer Multiple Remote Vulnerabilities
     40. SquirrelMail decodeHeader HTML Injection Vulnerability
     41. Multiple Vendor Server Response Filtering Weakness
     42. JWhois Double Free Memory Corruption Vulnerability
     43. EZ-IPupdate Remote Format String Vulnerability
     44. vBulletin LAST.PHP SQL Injection Vulnerability
     45. Cisco Security Agent Buffer Overflow Protection Bypass Vulne...
     46. Phorum FOLLOW.PHP SQL Injection Vulnerability
     47. Davfs2 Insecure Temporary File Creation Vulnerability
     48. ZoneLabs IMsecure URI Filter Bypass Vulnerability
     49. GD Graphics Library Multiple Unspecified Remote Buffer overf...
     50. Alcatel Speed Touch Pro With Firewall ADSL Router DNS Poison...
     51. ARJ Software UNARJ Remote Buffer Overflow Vulnerability
     52. Youngzsoft CCProxy Logging Function Unspecified Remote Buffe...
     53. OpenSkat Weak Encryption Key Generation Vulnerability
     54. GratiSoft Sudo Restricted Command Execution Bypass Vulnerabi...
     55. Clearswift MIMEsweeper For SMTP Encrypted Email Scanner Bypa...
     56. SecureAction Research Secure Network Messenger Remote Denial...
III. SECURITYFOCUS NEWS ARTICLES
     1. Defendant: Microsoft source code sale was a setup
     2. Banks prepare for ATM cyber crime
     3. Alleged DDoS kingpin joins most wanted list
     4. Cisco fixes 'decoy attack' in security software
     5. Anti-virus outfit defends job for VXer
     6. Say hello to the 'time bomb' exploit
IV. SECURITYFOCUS TOP 6 TOOLS
     1. ksb26-2.6.9 Kernel Socks Bouncer for 2.6.x kernels 2.6.9
     2. lock 2.0
     3. rootsh 0.2
     4. Basic Analysis and Security Engine (BASE) 0.9.8
     5. WapgGui 1.0
     6. VTrace 0.1
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Developer, Boulder, US (Thread)
     2. [SJ-JOB] Sr. Product Manager, Los Angeles , US (Thread)
     3. [SJ-JOB] Security Engineer, Reading, GB (Thread)
     4. [SJ-JOB] Security Product Manager, Dallas, US (Thread)
     5. [SJ-JOB] Security Consultant, Milwaukee, US (Thread)
     6. [SJ-JOB] VP of Marketing, Irvine, US (Thread)
     7. [SJ-JOB] Application Security Engineer, Farmington H... (Thread)
     8. [SJ-JOB] Manager, Information Security, West coast, ... (Thread)
     9. [SJ-JOB] Security Consultant, New York, US (Thread)
     10. [SJ-JOB] Sales Engineer, San Francisco, US (Thread)
     11. [SJ-JOB] Chief Security Strategist, Westfield Center... (Thread)
     12. [SJ-JOB] VP / Dir / Mgr engineering, San Francisco, ... (Thread)
     13. [SJ-JOB] Security Consultant, Herndon, US (Thread)
     14. [SJ-JOB] Security Director, Boston, US (Thread)
     15. [SJ-JOB] Security Architect, Dallas, US (Thread)
     16. [SJ-JOB] Manager, Information Security, Stamford, US (Thread)
     17. [SJ-JOB] Channel / Business Development, Santa Clara... (Thread)
     18. [SJ-JOB] Chief Scientist, San Francisco, US (Thread)
     19. [SJ-JOB] Quality Assurance, San Francisco, US (Thread)
     20. [SJ-JOB] Management, Boulder, US (Thread)
     21. [SJ-JOB] Security Consultant, San Francisco, US (Thread)
     22. [SJ-JOB] Sr. Security Engineer, Redwood City, US (Thread)
     23. [SJ-JOB] Security Engineer, Chicago, US (Thread)
     24. [SJ-JOB] Manager, Information Security, Milwaukee, U... (Thread)
     25. [SJ-JOB] Developer, Westminster, US (Thread)
     26. [SJ-JOB] Security Consultant, Grapevine, US (Thread)
     27. [SJ-JOB] Application Security Engineer, Geneva, CH (Thread)
     28. [SJ-JOB] Sr. Security Engineer, New York, US (Thread)
     29. [SJ-JOB] Developer, London, GB (Thread)
     30. [SJ-JOB] Jr. Security Analyst, New York, US (Thread)
     31. [SJ-JOB] Manager, Information Security, Wiltshire, G... (Thread)
     32. [SJ-JOB] Security System Administrator, Dallas, US (Thread)
     33. [SJ-JOB] Sr. Security Engineer, Fort Lauderdale, US (Thread)
     34. [SJ-JOB] Sales Engineer, Dallas, US (Thread)
     35. [SJ-JOB] Security Auditor, Fort Lauderdale, US (Thread)
     36. [SJ-JOB] Security Engineer, Redwood City, US (Thread)
     37. [SJ-JOB] Sr. Product Manager, San Jose, US (Thread)
     38. [SJ-JOB] Developer, Fort Lauderdale, US (Thread)
     39. [SJ-JOB] Sr. Product Manager, Redwood Shores, US (Thread)
     40. [SJ-JOB] Security Researcher, Alpharetta, GA, US (Thread)
     41. [SJ-JOB] Developer, Mansfield, US (Thread)
     42. [SJ-JOB] Sr. Security Engineer, Mansfield, US (Thread)
     43. [SJ-JOB] Application Security Engineer, Mansfield, U... (Thread)
     44. [SJ-JOB] Security System Administrator, Milton, CA (Thread)
     45. [SJ-JOB] Security Engineer, New York City or Northea... (Thread)
     46. [SJ-JOB] Sales Engineer, Chicago, US (Thread)
     47. [SJ-JOB] Sr. Product Manager, Sunnyvale, US (Thread)
     48. [SJ-JOB] Sales Engineer, Bay Area, US (Thread)
     49. [SJ-JOB] Sr. Security Analyst, Redwood Shores, US (Thread)
     50. [SJ-JOB] Account Manager, Washington, US (Thread)
     51. [SJ-JOB] Developer, San Francisco, US (Thread)
     52. [SJ-JOB] Sales Engineer, Boston Area, US (Thread)
     53. [SJ-JOB] Security Consultant, Mansfield, US (Thread)
     54. [SJ-JOB] Developer, BWI/Annapolis, US (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Malformed DNS or something odd (or just me) (Thread)
     2. ABoxInstall (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Buffer Overflow Help (Thread)
     2. Re[2]: TEB buffer+Return Into LIBC based string copy... (Thread)
     3. [off topic] Book, articles and link recommendations (Thread)
     4. non-executable stacks (Thread)
     5. TEB buffer+Return Into LIBC based string copy exploi... (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Supported products in Windows Security Center (WSC) (Thread)
     2. Microsoft rights management server alternatives (Thread)
     3. SecurityFocus Microsoft Newsletter #214 (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-11-09 to 2004-11-16.
X. LINUX FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-11-09 to 2004-11-16.
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. The Worst Case Scenario
By Mark Rasch

The fine print in an insurance policy becomes an issue when a bizarre chain
of IT disasters leaves a company without a single copy of the source code
to its flagship product.

http://www.securityfocus.com/columnists/276

II. BUGTRAQ SUMMARY
-------------------
1. Gentoo Linux Multiple PDF EBuild Updates Unspecified Vulnera...
BugTraq ID: 11614
Remote: Yes
Date Published: Nov 06 2004
Relevant URL: http://www.securityfocus.com/bid/11614
Summary:
Gentoo Linux released updated Xpdf, CUPS, GPdf, KPDF and KOffice eBuilds to address the vulnerability described in BID 11501 (Xpdf PDFTOPS Multiple Integer Overflow Vulnerabilities) on October 28, 2004.

The vendor has reported that these updated eBuilds introduced an unspecified vulnerability. The vulnerability is reported to present itself only on 64-bit platforms.

2. Software602 602 LAN Suite Multiple Remote Denial Of Service ...
BugTraq ID: 11615
Remote: Yes
Date Published: Nov 06 2004
Relevant URL: http://www.securityfocus.com/bid/11615
Summary:
602 LAN SUITE is reported prone to multiple remote denial of service vulnerabilities. The following specific issues are reported:

It is reported that an attacker may consume CPU and memory resources on a target 602 LAN SUITE server. Reports indicate that this condition exists due to a lack of sanity checking prior to the allocation of regions of memory by the affected software. 

A remote attacker may exploit this vulnerability to consume system resources, ultimately impacting the performance of the target computer and potentially resulting in a denial of service.

A second vulnerability is reported in the manner in which 602 LAN SUITE handles telnet proxy requests. It is reported that the proxy does not perform sufficient sanity checks on the destination IP of a proxy request.

A remote attacker may exploit this condition to exhaust all available sockets on a target computer that is running 602 LAN SUITE telnet proxy. This will effectively deny service to legitimate requests.

3. Gentoo Portage Dispatch-Conf Insecure Temporary File Creatio...
BugTraq ID: 11616
Remote: No
Date Published: Nov 07 2004
Relevant URL: http://www.securityfocus.com/bid/11616
Summary:
The Gentoo dispatch-conf script is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.

An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.

4. Gentoo Gentoolkit QPKG Insecure Temporary File Creation Vuln...
BugTraq ID: 11617
Remote: No
Date Published: Nov 07 2004
Relevant URL: http://www.securityfocus.com/bid/11617
Summary:
The qpkg utility is affected by an unspecified insecure temporary file creation vulnerability.  This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.

An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.

5. Yukihiro Matsumoto Ruby CGI Module Unspecified Denial Of Ser...
BugTraq ID: 11618
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11618
Summary:
Ruby is reported prone to a remote denial of service vulnerability. It is reported that when the Ruby CGI module handles certain requests, it may fall into an infinite loop and consume system CPU resources.

A remote attacker may exploit this vulnerability to deny service to a computer that is running the affected Ruby CGI module.

6. Sun Java Runtime Environment InitialDirContext Remote Denial...
BugTraq ID: 11619
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11619
Summary:
A remote denial of service vulnerability reportedly affects the Sun Java Runtime Environment.  This issue is due to a design error that fails to keep track of DNS requests.

An attacker may leverage this issue to cause an application running on the affected software to fail to make DNS requests, causing a denial of service condition on network-based Java applications.

7. MiniShare Server Remote Buffer Overflow Vulnerability
BugTraq ID: 11620
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11620
Summary:
It is reported that MiniShare is susceptible to a remote buffer overflow vulnerability. This issue is due to insufficient buffer boundary verification prior to copying user-supplied data.

This vulnerability allows remote attackers to execute arbitrary code in the context of the affected application.

Version 1.4.1 of MiniShare is reported vulnerable to this issue. Other versions may also be affected.

8. Microsoft Internet Explorer Local Resource Enumeration Vulne...
BugTraq ID: 11621
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11621
Summary:
Microsoft Internet Explorer is reported prone to a local resource enumeration vulnerability. It is reported that the vulnerability exists because when handling 'res://' requests for local resources, Internet explorer behavior may reveal the existence of local files.

An attacker may employ information that is harvested in this manner to aid in further attacks that are launched against a target computer.

9. Mantis Multiple Information Disclosure Vulnerabilities
BugTraq ID: 11622
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11622
Summary:
Mantis is reported prone to multiple information disclosure vulnerabilities. The following specific issues are reported:

It is reported that users added to a project and then removed from the project may still receive updates for bugs that they have set themselves to monitor.

Additionally it is reported that a user may view stats of all projects even though the user is only assigned to a single project.

An attacker may employ information that is harvested from exploitation of these vulnerabilities to aid in further attacks that are launched against a target network.

10. Nortel Contivity VPN Client Username Enumeration Vulnerabili...
BugTraq ID: 11623
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11623
Summary:
It is reported that Nortel Contivity VPN client is susceptible to a username enumeration vulnerability.

Attackers may exploit this vulnerability to discern valid usernames. This may aid them in brute force password cracking, or other attacks.

Versions prior to 5.01_030 are reported susceptible to this issue.

11. Samba Remote Wild Card Denial Of Service Vulnerability
BugTraq ID: 11624
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11624
Summary:
A remote denial of service vulnerability affects the wild card file name functionality of Samba.  This issue is caused due to a failure of the application to properly validate malformed user-supplied strings.

An attacker may leverage this issue to cause the affected application to hang, effectively denying service to legitimate users.

12. EGroupWare JiNN Application Unspecified Vulnerability
BugTraq ID: 11625
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11625
Summary:
eGroupWare JiNN application is reported prone to an unspecified vulnerability.

Further details of this issue are not available at the time of writing. This BID will be updated as details are released.

13. Pavuk Multiple Unspecified Remote Buffer Overflow Vulnerabil...
BugTraq ID: 11626
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11626
Summary:
Pavuk is reported prone to multiple unspecified remote buffer overflow vulnerabilities.  These issue exist due to insufficient boundary checks performed by the application.  A remote attacker may exploit these vulnerabilities to cause a denial of service condition or execute arbitrary code on a vulnerable computer.

In addition to these vulnerabilities, Pavuk is reported prone to other buffer overflow vulnerabilities affecting the digest authentication handler and the HTTP header processing functionality.  It is likely that these issues are related to BIDS 10633 and 10797.  This information cannot be confirmed at the moment.  This BID will be updated as more information becomes available.

Pavuk versions 0.9pl30b and prior are affected by these vulnerabilities.

14. JAF CMS Directory Traversal Vulnerability Allowing Script Co...
BugTraq ID: 11627
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11627
Summary:
It is reported that JAF CMS is susceptible to a directory traversal vulnerability allowing information disclosure and server-side script execution. This issue is due to a failure of the application to properly sanitize user-supplied URI input.

To execute arbitrary PHP script code, the attacker requires the ability to create or modify files on the computer hosting the affected application.

This vulnerability may be exploited by remote attackers to execute server-side PHP script code in the context of the affected application, or to gain access to the contents of arbitrary, potentially sensitive files with the privileges of the Web server.

Version 3.0 RC and prior are reported vulnerable to this issue.

15. StarForce Professional Software Protection Local Privilege E...
BugTraq ID: 11628
Remote: No
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11628
Summary:
StarForce Professional Software Protection is reported prone to a local privilege escalation vulnerability. It is reported that the drivers that are installed when installing software that is protected by StarForce provide for this escalation.

16. GFHost Cross-Site Scripting And Server-Side Script Execution...
BugTraq ID: 11629
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11629
Summary:
It is reported that GFHost is susceptible to a cross-site scripting vulnerability, and a server-side script execution vulnerability. These issues are due to a failure of the application to properly sanitize user-supplied input.

The cross-site scripting issue could permit a remote attacker to cause hostile HTML or script code to be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

Ths script execution vulnerability reportedly allows remote attackers to execute arbitrary PHP script code in the context of the affected Web application.

17. Up-IMAPProxy Multiple Remote Vulnerabilities
BugTraq ID: 11630
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11630
Summary:
up-imapproxy is reported prone to multiple remote vulnerabilities. The following specific issues are reported:

It is reported that multiple denial of service conditions exist in the way up-imapproxy handles literal values. Literal data processed by affected functions will result in a denial of service. Additionally, a literal value passed as a command to the affected service will result in a denial of service if the command does not exist.

A remote attacker may exploit these vulnerabilities to crash the affected service effectively denying service to legitimate users.

Finally, it is reported that literal value sizes are stored in signed integer format. The discoverer of these vulnerabilities reports that this may result in a boundary condition on 64-bit platforms.

A remote attacker may potentially exploit this condition to reveal potentially sensitive data. 

It should be noted that reports indicate that up-imapproxy may not actually execute on 64-bit platforms.

18. Nucleus CMS Multiple Unspecified Input Validation Vulnerabil...
BugTraq ID: 11631
Remote: Yes
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11631
Summary:
Multiple unspecified vulnerabilities reportedly affect Nucleus CMS.  These issue are due to a failure of the application to properly sanitize user-supplied input prior to employing it in critical locations including dynamic content and database queries.

A remote attacker may leverage these issues to steal cookie-based authentication credentials, reveal sensitive data and corrupt database contents.

19. Infusium ASP Message Board Multiple Unspecified Input Valida...
BugTraq ID: 11632
Remote: Yes
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11632
Summary:
Multiple unspecified vulnerabilities reportedly affect the Infusium ASP Message Board.  These issue are due to a failure of the application to properly sanitize user-supplied input prior to employing it in critical locations including dynamic content and database queries.

A remote attacker may leverage these issues to steal cookie-based authentication credentials, reveal sensitive data and corrupt database contents.

20. SQLgrey Postfix Greylisting Service SQL Injection Vulnerabil...
BugTraq ID: 11633
Remote: Yes
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11633
Summary:
SQLgrey Postfix Greylisting Service is prone to an SQL injection vulnerability.  This issue is reportedly due to insufficient sanitization of SQL syntax from fields in email processed by the software.  

The issue could be exploited to influence SQL queries, potentially allowing for compromise of the software or other attacks that impact database security.

21. Netgear DG834 ADSL Firewall Router Multiple Vulnerabilities
BugTraq ID: 11634
Remote: Yes
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11634
Summary:
Netgear DG834 ADSL Firewall Router is reported prone to multiple remote vulnerabilities.  These vulnerabilities can allow remote attackers to carry out denial of service attacks against the device's Web interface or bypass filter rules.

22. Samhain Labs Samhain Database Update Local Heap Overflow Vul...
BugTraq ID: 11635
Remote: No
Date Published: Nov 08 2004
Relevant URL: http://www.securityfocus.com/bid/11635
Summary:
A locally exploitable heap-based buffer overflow exists in Samhain.  This issue is exposed when the database is run in update mode and may allow a malicious local user to execute arbitrary code with superuser privileges if successfully exploited.

23. Sun One/IPlanet Messaging Server Webmail Unauthorized Email ...
BugTraq ID: 11636
Remote: Yes
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11636
Summary:
Sun One/IPlanet Messaging Server is reported prone to an unauthorized email account access vulnerability.  The vendor has confirmed that a remote attacker can exploit this issue through a specially crafted email message to access another user's email account.

iPlanet Messaging Server 5.2 and  Sun ONE Messaging Server 6.1 are affected by this issue.

24. Microsoft Internet Explorer Embedded Content Status Bar URI ...
BugTraq ID: 11637
Remote: Yes
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11637
Summary:
Microsoft Internet Explorer is reported prone to a status bar URI obfuscation weakness. The issue presents itself when an embedded object is encapsulated in a HREF tag.

This issue may be leveraged by an attacker to display false information in the status bar of the browser of an unsuspecting user, allowing an attacker to present web pages to users that seem to originate from a trusted location. This may facilitate phishing style attacks; other attacks may also be possible.

25. Microsoft Windows DDEShare Buffer Overflow Vulnerability
BugTraq ID: 11638
Remote: Yes
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11638
Summary:
A buffer overflow vulnerability is reported to affect the Microsoft Windows 'ddeshare.exe' utility.

Although unconfirmed it is conjectured that a remote attacker may potentially exploit this condition to execute arbitrary code in the context of a user that is employing the affected utility to process a malicious remote DDE share name.

26. Kerio Personal Firewall IP Options Denial Of Service Vulnera...
BugTraq ID: 11639
Remote: Yes
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11639
Summary:
A remote denial of service vulnerability affects the IP options filtering functionality of Kerio's Personal Firewall.  This issue is caused by a failure of the application to properly handle malformed network packets.

A remote attacker can exploit this issue anonymously with a spoofed packet to cause a computer running the affected application to hang indefinitely, denying service to legitimate users.

27. MTink Insecure Temporary File Creation Vulnerability
BugTraq ID: 11640
Remote: No
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11640
Summary:
The MTink package is affected by an unspecified insecure temporary file creation vulnerability.  This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.

An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.

28. PvPGN GameReport Packet Handler Remote Buffer Overflow Vulne...
BugTraq ID: 11641
Remote: Yes
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11641
Summary:
PvPGN is reported prone to a remote buffer overflow vulnerability.  This issue may allow an attacker to execute arbitrary code to gain unauthorized access to a vulnerable computer.

The issue exists due to insufficient boundary checks performed on 'gamereport' packets by the software.

This issue may result in a denial of service condition. If an attacker succeeds in overwriting sensitive process memory and redirecting process execution to malicious arbitrary code, this issue may allow the attacker to gain unauthorized access to a vulnerable computer.

29. Multiple Vendor DNS Response Flooding Denial Of Service Vuln...
BugTraq ID: 11642
Remote: Yes
Date Published: Nov 09 2004
Relevant URL: http://www.securityfocus.com/bid/11642
Summary:
Multiple DNS vendors are reported susceptible to a denial of service vulnerability.

This vulnerability results in vulnerable DNS servers entering into an infinite query and response message loop, leading to the consumption of network and CPU resources, and denying DNS service to legitimate users.

30. Mozilla Firefox Download Dialogue Box File Name Spoofing Vul...
BugTraq ID: 11643
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11643
Summary:
A download dialogue box file name spoofing vulnerability affects Mozilla Firefox.  This issue is due to a design error that facilitates the spoofing of file names.

An attacker may leverage this issue to spoof downloaded file names to unsuspecting users.  This issue may lead to a compromise of the target computer as well as other consequences.

NOTE:  This issue has been fixed by reducing the number of space characters displayed in the dialogue box.  It should be noted that this issue may still be triggered by using other characters to fill the space such as non-displayable characters and even extremely long file names.  Users should be cautious about downloading files with the affected application.

31. Mozilla Firefox Insecure Default Installation Vulnerability
BugTraq ID: 11644
Remote: No
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11644
Summary:
Mozilla Firefox is a Web browser developed and supported by the Mozilla Organization. It is freely available for most UNIX and Linux based operating systems as well as Microsoft Windows.

An insecure default installation vulnerability affects Mozilla Firefox.  This issue is due to a failure of the application to place secure permissions on installed files.  It should be noted that this issue only affects the vulnerable application installed on the Apple Mac OS X platform.

An unsuspecting user that double-clicks on such an affected application may have attacker-specified code executing with their privileges, potentially facilitating privilege escalation.

32. WhitSoft Development SlimFTPd Remote Buffer Overflow Vulnera...
BugTraq ID: 11645
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11645
Summary:
A remote buffer overflow vulnerability affects WhitSoft Development SlimFTPd.  This issue is due to a failure of the application to perform proper bounds checking on user-supplied strings prior to copying them into process buffers.

An attacker can leverage this issue to execute arbitrary machine code with the privileges of the affected FTP server, facilitating unauthorized access and privilege escalation.

33. Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vu...
BugTraq ID: 11646
Remote: No
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11646
Summary:
Multiple vulnerabilities have been identified in the Linux ELF binary loader.  These issues can allow local attackers to gain elevated privileges.  The source of these issues is present in the 'load_elf_binary' function of the 'binfmt_elf.c' file.

The first issue results from an improper check performed on the return value of the 'kernel_read' function.  An attacker may gain control over execution flow of a setuid binary by modifying the memory layout of a binary. 

The second issue results from improper error handling when the mmap() function fails.

The third vulnerability results from a bad return value when the program interpreter (linker) is mapped into memory.  It is reported that this issue only occurs in the 2.4.x versions of the Linux kernel.

The fourth vulnerable condition presents itself because a user can execute a binary with a malformed interpreter name string.  This issue can lead to a system crash.

The final issue exists in the execve() code.  This issue may allow an attacker to disclose sensitive data that can potentially be used to gain elevated privileges.

These issues are currently undergoing further analysis.  This BID will be updated and divided into separate BIDS in the future.

34. BNC getnickuserhost IRC Server Response Buffer Overflow Vuln...
BugTraq ID: 11647
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11647
Summary:
A remotely exploitable stack-based buffer overflow has been reported in BNC.  This issue may be triggered when a malformed IRC (Internet Relay Chat) server response is handled by the proxy.  

If successfully exploited, this would allow execution of arbitrary code in the context of the proxy.

35. Multiple Browser IMG Tag Multiple Vulnerabilities
BugTraq ID: 11648
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11648
Summary:
Various browsers are reported prone to multiple vulnerabilities in the image handling functionality through the <IMG> tag.  These issues can allow remote attackers to determine the existence of local files, cause a denial of service condition, and disclose passwords for Windows systems via file shares.

Mozilla Firefox 0.10.1 and prior versions are reported vulnerable to these issues.  It is alleged that Microsoft Internet Explorer and Netscape Browsers are also vulnerable to these issues.  Due to this vulnerable packages for Internet Explorer and Netscape have been added.  This BID will be updated as more information becomes available.

36. Cisco IOS DHCP Input Queue Blocking Denial Of Service Vulner...
BugTraq ID: 11649
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11649
Summary:
Cisco IOS is reported susceptible to a remote denial of service vulnerability when handling specific DHCP packets.

Reportedly, DHCP packets containing certain unspecified content have the capability to block the input queue of interfaces on affected devices.

Once an input queue is blocked, further ARP, and routing protocol packets will not be processed. This condition can only be corrected by rebooting the affected device.

An attacker with the ability to send malicious DHCP packets to an affected device may be able to interrupt the routing services of the affected device, potentially denying further network service to legitimate users.

37. BNC IRC Server Proxy Authentication Bypass Vulnerability
BugTraq ID: 11650
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11650
Summary:
BNC is reported prone to an authentication bypass vulnerability.  It is reported by the vendor that only users with incorrect passwords were granted access to the resources.

It is possible that this issue surfaced due to code modifications after the recent release of BNC 2.9.0, which addresses various issues including a security vulnerability (BID 11647).

Due to a lack of details, further information is not available at the moment.  This BID will be updated as more information becomes available.

38. WebCalendar Multiple Remote Vulnerabilities
BugTraq ID: 11651
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11651
Summary:
Multiple remote vulnerabilities are reported to exist in WebCalendar.

Multiple cross-site scripting vulnerabilites, an HTTP response splitting vulnerability, and two authentication bypass vulnerabilities are reported to exist in many different scripts in the affected application.

Fixes are reported to exist in the CVS version of the software.

39. 04WebServer Multiple Remote Vulnerabilities
BugTraq ID: 11652
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11652
Summary:
Multiple remote vulnerabilities reportedly affect 04WebServer.  These issues are due to a failure of the application to properly sanitize user-supplied input.

An attacker may leverage these issues to carry out cross-site scripting attacks against any Web sites hosted on the affected server and to inject arbitrary characters into log files, potentially leading to corruption.

40. SquirrelMail decodeHeader HTML Injection Vulnerability
BugTraq ID: 11653
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11653
Summary:
SquirrelMail is reported to be prone to an email header HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied email header strings.

An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.

41. Multiple Vendor Server Response Filtering Weakness
BugTraq ID: 11655
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11655
Summary:
It has been reported that multiple vendor's servers are affected by a server response splitting weakness.

An attacker may leverage these issues to have attacker-specified data echoed back to the computer that the request originated from.  This may facilitate various attacks including cross-site scripting attacks in Web browsers through concurrent exploitation of the issues outlined in BID 3181 (Multiple Vendor HTML Form Protocol Vulnerability).

42. JWhois Double Free Memory Corruption Vulnerability
BugTraq ID: 11656
Remote: Yes
Date Published: Nov 10 2004
Relevant URL: http://www.securityfocus.com/bid/11656
Summary:
It is reported that jwhois is susceptible to a double free vulnerability.

If jwhois attempts to process whois requests that result in more than one redirection, it is reported that a double free condition will occur.

It is conjectured that it may be possible for remote attackers to exploit this vulnerability to write to arbitrary locations in memory, facilitating the execution of attacker-supplied code. This has not been confirmed.

This vulnerability may not actually be exploitable. This BID will be updated or retired as further information is disclosed.

43. EZ-IPupdate Remote Format String Vulnerability
BugTraq ID: 11657
Remote: Yes
Date Published: Nov 11 2004
Relevant URL: http://www.securityfocus.com/bid/11657
Summary:
EZ-IPupdate is vulnerable to a remotely exploitable format string vulnerability when running in daemon-mode.  The vulnerability is present even if "quiet" mode is enabled.

44. vBulletin LAST.PHP SQL Injection Vulnerability
BugTraq ID: 11658
Remote: Yes
Date Published: Nov 11 2004
Relevant URL: http://www.securityfocus.com/bid/11658
Summary:
vBulletin is reported vulnerable to a remote SQL injection vulnerability. This issue is due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query.

An attacker exploits this issue to manipulate and inject SQL queries onto the underlying database. It is reportedly possible to leverage this issue to steal database contents including administrator password hashes and user credentials as well as to attack the underlying database.

Update: It is reported that this vulnerability exists in third party scripts that can be used with vBulletin.  Currently, the vendor of the affected scripts is not known.  This BID will be updated as more information becomes available.

45. Cisco Security Agent Buffer Overflow Protection Bypass Vulne...
BugTraq ID: 11659
Remote: Yes
Date Published: Nov 11 2004
Relevant URL: http://www.securityfocus.com/bid/11659
Summary:
It is reported that Cisco Security Agent is susceptible to a buffer overflow protection bypass vulnerability.

This vulnerability allows remote attackers to bypass the buffer overflow protections offered by Cisco Security Agent. This aids attackers in exploiting latent vulnerabilities in services protected by the affected package.

Versions prior to 4.0.3.728 are reported susceptible to this vulnerability.

46. Phorum FOLLOW.PHP SQL Injection Vulnerability
BugTraq ID: 11660
Remote: Yes
Date Published: Nov 11 2004
Relevant URL: http://www.securityfocus.com/bid/11660
Summary:
Reportedly Phorum is affected by a remote SQL injection vulnerability. This issue is due to a failure of the application to properly sanitized user supplied URI input.

This issue allows remote attackers to manipulate query logic, leading to unauthorized access to sensitive information such as the user password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.

This issue has been reported to affected versions prior to 5.0.13.

47. Davfs2 Insecure Temporary File Creation Vulnerability
BugTraq ID: 11661
Remote: No
Date Published: Nov 11 2004
Relevant URL: http://www.securityfocus.com/bid/11661
Summary:
Davfs2 is affected by an insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify a files existence before writing to it.

An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.

48. ZoneLabs IMsecure URI Filter Bypass Vulnerability
BugTraq ID: 11662
Remote: Yes
Date Published: Nov 11 2004
Relevant URL: http://www.securityfocus.com/bid/11662
Summary:
It is reported that IMsecure is vulnerable to a filter bypass vulnerability.

This vulnerability allows remote attackers to bypass the security filter of the affected product.

Versions prior to 1.5.0.39 are reportedly affected by this vulnerability.

49. GD Graphics Library Multiple Unspecified Remote Buffer overf...
BugTraq ID: 11663
Remote: Yes
Date Published: Nov 12 2004
Relevant URL: http://www.securityfocus.com/bid/11663
Summary:
Multiple unspecified remote buffer overflow vulnerabilities have been identified in the GD Graphics Library.  These issues are due to a failure of the library to do sufficient bounds checking prior to processing user-specified strings.

An attacker may leverage these issues to remotely execute arbitrary code on a computer with the privileges of a user that views a malicious image file.  This may facilitate unauthorized access or privilege escalation.

50. Alcatel Speed Touch Pro With Firewall ADSL Router DNS Poison...
BugTraq ID: 11664
Remote: Yes
Date Published: Nov 12 2004
Relevant URL: http://www.securityfocus.com/bid/11664
Summary:
Speed Touch Pro With Firewall ADSL Router is reported prone to a DNS poisoning vulnerability.  This issue can allow remote attackers to spoof addresses, carry out man-in-the-middle attacks, and trigger potential denial of service conditions.

51. ARJ Software UNARJ Remote Buffer Overflow Vulnerability
BugTraq ID: 11665
Remote: Yes
Date Published: Nov 12 2004
Relevant URL: http://www.securityfocus.com/bid/11665
Summary:
A remote buffer overflow vulnerability affects ARJ Software's unarj.  This issue is caused by a failure of the application to carry out sufficient bounds checking on user-supplied strings prior to processing.

A remote attacker may leverage this issue to execute arbitrary code with the privileges of a user that process a malicious file with the affected application.  This may facilitate unauthorized access or privilege escalation.

52. Youngzsoft CCProxy Logging Function Unspecified Remote Buffe...
BugTraq ID: 11666
Remote: Yes
Date Published: Nov 11 2004
Relevant URL: http://www.securityfocus.com/bid/11666
Summary:
CCProxy is reported prone to an unspecified remote buffer overflow vulnerability.  This issue may allow remote attackers to execute arbitrary code on a vulnerable computer, which can allow for unauthorized access.

All versions of CCProxy are considered vulnerable at the moment.

53. OpenSkat Weak Encryption Key Generation Vulnerability
BugTraq ID: 11667
Remote: Yes
Date Published: Nov 12 2004
Relevant URL: http://www.securityfocus.com/bid/11667
Summary:
A weak encryption key generation vulnerability affects openSkat.  This issue is due to a design error that causes the application to generate weak encryption keys.

An attacker may leverage this issue to derive the private keys of a user running the vulnerable application through factorization attacks.

54. GratiSoft Sudo Restricted Command Execution Bypass Vulnerabi...
BugTraq ID: 11668
Remote: No
Date Published: Nov 12 2004
Relevant URL: http://www.securityfocus.com/bid/11668
Summary:
A restricted command execution bypass vulnerability affects GratiSoft's Sudo application.  This issue is due to a design error that causes the application to fail to properly sanitize user-supplied environment variables.

An attacker with sudo privileges may leverage this issue to execute commands that are explicitly disallowed.  This may facilitate privileges escalation and certainly leads to a false sense of security.

55. Clearswift MIMEsweeper For SMTP Encrypted Email Scanner Bypa...
BugTraq ID: 11669
Remote: Yes
Date Published: Nov 11 2004
Relevant URL: http://www.securityfocus.com/bid/11669
Summary:
A vulnerability has been reported in Clearswift MIMEsweeper that may result in malicious emails bypassing the scanner.  This is due to an issue in classifying encrypted emails, causing them to be marked as "clean" instead of being properly flagged as "encrypted".

This issue affects users who have upgraded to MIMEsweeper for SMTP 5.0 from MAILsweeper Business Suite I, MAILsweeper Business Suite II, or MAILsweeper for SMTP version 4.3.  Fresh installs of MIMEsweeper for SMTP 5.0 are not affected.

56. SecureAction Research Secure Network Messenger Remote Denial...
BugTraq ID: 11670
Remote: Yes
Date Published: Nov 12 2004
Relevant URL: http://www.securityfocus.com/bid/11670
Summary:
A remote denial of service vulnerability affects SecureAction Research Secure Network Messenger.  This issue is due to a failure of the application to properly handle exceptional network data.

An attacker may leverage this issue to cause a computer running the vulnerable application to crash, denying service to legitimate users.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Defendant: Microsoft source code sale was a setup
By: Kevin Poulsen

A Connecticut man facing economic espionage charges says he wasn't serious about selling already-leaked Microsoft source code, but an undercover investigator for the software giant was determined to pay him something.

http://www.securityfocus.com/news/9912

2. Banks prepare for ATM cyber crime
By: Kevin Poulsen

An industry and law enforcement group hopes to prevent Windows XP-based cash machines from inspiring "the next wave of ATM crime."

http://www.securityfocus.com/news/9903

3. Alleged DDoS kingpin joins most wanted list
By: Kevin Poulsen

The feds turn up the heat on a corporate executive who went on the lam after being charged with paying hackers to take down the competition.  

http://www.securityfocus.com/news/9870

4. Cisco fixes 'decoy attack' in security software
By: John Leyden, The Register

Cisco has discovered a security flaw in its Cisco Security Agent software (CSA. This could be exploited by attackers to circumvent the security provided by the host-based intrusion prevention product.
http://www.securityfocus.com/news/9937

5. Anti-virus outfit defends job for VXer
By: John Leyden, The Register

Czech company Zoner Software has explained why it employed a prominent former virus writer to develop anti-virus software on its behalf.
http://www.securityfocus.com/news/9918

6. Say hello to the 'time bomb' exploit
By: , The Register

Prepare yourself for "time bomb" exploits that attack web-based systems at a pre-determined time.

http://www.securityfocus.com/news/9917

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. ksb26-2.6.9 Kernel Socks Bouncer for 2.6.x kernels 2.6.9
By: Paolo Ardoino
Relevant URL: http://ardoino.altervista.org/kernel.php
Platforms: Linux
Summary: 

KSB26 [Kernel Socks Bouncer] is Linux Kernel 2.6.x patch that redirects full tcp connections [SSH, telnet, ...] to follow through socks5. KSB26 uses a character device to pass socks5 and target ips to the Linux Kernel. I have choosen to write in kernel space to enjoy myself [I know that there are easier and safer ways to write this in userspace].

2. lock 2.0
By: Uri Fridman
Relevant URL: http://www.geocities.com/urifrid/lock-2.0-src.zip
Platforms: Windows 2000
Summary: 

Lock is a command line tool to lock the
workstation, options include:
- lock the workstation
- lock workstation and run default
screensaver
- minimize all open windows and lock the
workstation
- send the system to sleep (standby)

open source, free and small.

3. rootsh 0.2
By: Gerhard Lausser
Relevant URL: http://sourceforge.net/projects/rootsh/
Platforms: AIX, HP-UX, Linux, POSIX, SINIX, Solaris, UNIX
Summary: 

Rootsh is a wrapper for shells which logs all echoed keystrokes and terminal output to a file and/or to syslog. It's main purpose is the auditing of users who need a shell with root privileges. They start rootsh through the sudo mechanism. I's in heavy use here at a big bavarian car manufacturer (three letters, fast, cool,...) for project users whom you can't deny root privileges.

4. Basic Analysis and Security Engine (BASE) 0.9.8
By: Kevin Johnson and the BASE team
Relevant URL: http://sourceforge.net/projects/secureideas
Platforms: PHP
Summary: 

BASE is the Basic Analysis and Security Engine. It is based on the code from the Analysis Console for Intrusion Databases (ACID) project. This application provides a web front-end to query and analyze the alerts coming from a SNORT IDS system.

5. WapgGui 1.0
By: William D. Bartholomew
Relevant URL: http://www.bartholomew.id.au/Default.aspx?tabid=32
Platforms: Windows 2000, Windows XP
Summary: 

A free, open-source, user-friendly interface to run the WAPG password generator. Supports generation of random and pronounceable passwords, specifying minimum and maximum length, specifying what character classes should or must be used, and much more.

6. VTrace 0.1
By: Emilio Cini
Relevant URL: http://www.guerradigital.com.br/vtrace/vtrace.zip
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

Tool for visual tracert, exhibiting the geographical location of each it plans that the package travels ties to arrive to the specified domain.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Developer, Boulder, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381238

2. [SJ-JOB] Sr. Product Manager, Los Angeles , US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381221

3. [SJ-JOB] Security Engineer, Reading, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381204

4. [SJ-JOB] Security Product Manager, Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381178

5. [SJ-JOB] Security Consultant, Milwaukee, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381176

6. [SJ-JOB] VP of Marketing, Irvine, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381175

7. [SJ-JOB] Application Security Engineer, Farmington H... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381174

8. [SJ-JOB] Manager, Information Security, West coast, ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381173

9. [SJ-JOB] Security Consultant, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381172

10. [SJ-JOB] Sales Engineer, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381167

11. [SJ-JOB] Chief Security Strategist, Westfield Center... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381163

12. [SJ-JOB] VP / Dir / Mgr engineering, San Francisco, ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381160

13. [SJ-JOB] Security Consultant, Herndon, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381159

14. [SJ-JOB] Security Director, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381149

15. [SJ-JOB] Security Architect, Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381147

16. [SJ-JOB] Manager, Information Security, Stamford, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381144

17. [SJ-JOB] Channel / Business Development, Santa Clara... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381140

18. [SJ-JOB] Chief Scientist, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381139

19. [SJ-JOB] Quality Assurance, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381138

20. [SJ-JOB] Management, Boulder, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381136

21. [SJ-JOB] Security Consultant, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381135

22. [SJ-JOB] Sr. Security Engineer, Redwood City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381134

23. [SJ-JOB] Security Engineer, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381132

24. [SJ-JOB] Manager, Information Security, Milwaukee, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381130

25. [SJ-JOB] Developer, Westminster, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381129

26. [SJ-JOB] Security Consultant, Grapevine, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381125

27. [SJ-JOB] Application Security Engineer, Geneva, CH (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380806

28. [SJ-JOB] Sr. Security Engineer, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380805

29. [SJ-JOB] Developer, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380804

30. [SJ-JOB] Jr. Security Analyst, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380798

31. [SJ-JOB] Manager, Information Security, Wiltshire, G... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380797

32. [SJ-JOB] Security System Administrator, Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380753

33. [SJ-JOB] Sr. Security Engineer, Fort Lauderdale, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380751

34. [SJ-JOB] Sales Engineer, Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380750

35. [SJ-JOB] Security Auditor, Fort Lauderdale, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380745

36. [SJ-JOB] Security Engineer, Redwood City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380744

37. [SJ-JOB] Sr. Product Manager, San Jose, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380730

38. [SJ-JOB] Developer, Fort Lauderdale, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380728

39. [SJ-JOB] Sr. Product Manager, Redwood Shores, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380696

40. [SJ-JOB] Security Researcher, Alpharetta, GA, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380693

41. [SJ-JOB] Developer, Mansfield, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380689

42. [SJ-JOB] Sr. Security Engineer, Mansfield, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380687

43. [SJ-JOB] Application Security Engineer, Mansfield, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380686

44. [SJ-JOB] Security System Administrator, Milton, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380685

45. [SJ-JOB] Security Engineer, New York City or Northea... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380684

46. [SJ-JOB] Sales Engineer, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380683

47. [SJ-JOB] Sr. Product Manager, Sunnyvale, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380682

48. [SJ-JOB] Sales Engineer, Bay Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380681

49. [SJ-JOB] Sr. Security Analyst, Redwood Shores, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380676

50. [SJ-JOB] Account Manager, Washington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380675

51. [SJ-JOB] Developer, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380670

52. [SJ-JOB] Sales Engineer, Boston Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380665

53. [SJ-JOB] Security Consultant, Mansfield, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380663

54. [SJ-JOB] Developer, BWI/Annapolis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380658

VI. INCIDENTS LIST SUMMARY
--------------------------
1. Malformed DNS or something odd (or just me) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/381051

2. ABoxInstall (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/381050

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Buffer Overflow Help (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/381158

2. Re[2]: TEB buffer+Return Into LIBC based string copy... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/381116

3. [off topic] Book, articles and link recommendations (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/381115

4. non-executable stacks (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/381094

5. TEB buffer+Return Into LIBC based string copy exploi... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/380931

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Supported products in Windows Security Center (WSC) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/381203

2. Microsoft rights management server alternatives (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/381142

3. SecurityFocus Microsoft Newsletter #214 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/381012

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-11-09 to 2004-11-16.

X. LINUX FOCUS LIST SUMMARY
---------------------------
NO NEW POSTS FOR THE WEEK 2004-11-09 to 2004-11-16.

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: Symantec

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041116

------------------------------------------------------------------------